Netgear FS728TLP Web Management User Guide - Page 311

MAC ACL Sample Configuration, To create such a MAC-based ACL

Page 311 highlights

ProSAFE FS526Tv2, FS726Tv2, and FS728TLP Smart Switches default deny all traffic rule that is the last rule of the MAC ACL table. (MAC ACL rules have a lower priority than IP ACL rules.) 2. Applying the ACL to an interface in the inbound direction. The smart switch allows ACLs to be bound to physical ports and LAGs. The smart switch supports MAC ACLs and IP ACLs. An example of each is provided in the following sections. MAC ACL Sample Configuration The following example shows how to create a MAC-based ACL that permits Ethernet traffic from the sales department on specified ports and denies all other traffic on those interfaces.  To create such a MAC-based ACL: 1. Select Security > ACL > Basic > MAC ACL. The MAC ACL screen displays. 2. Create an ACL with the name Sales_ACL for the sales department of your network. By default, this ACL is bound on the inbound direction, which means the smart switch examines traffic as it enters the port. For more information about creating named MAC ACLs, see Manage MAC ACL Names on page 197. 3. Select Security > ACL > Basic > MAC Rules. The MAC Rules screen displays. 4. Create a rule for the Sales_ACL with the following settings: Field or Menu ID Action Assign Queue Redirect Interface Match Every CoS Destination MAC Destination MAC Mask EtherType Key. EtherType User Value Source MAC Configuration Setting 1 Permit 0 Do not select False 0 01:02:1A:BC:DE:EF 00:00:00:00:FF:FF Do not enter Do not enter 02:02:1A:BC:DE:EF Configuration Examples 311

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312
  • 313
  • 314
  • 315
  • 316
  • 317
  • 318
  • 319
  • 320
  • 321
  • 322
  • 323
  • 324
  • 325
  • 326
  • 327
  • 328
  • 329
  • 330
  • 331
  • 332
  • 333
  • 334
  • 335

Configuration Examples
311
ProSAFE FS526Tv2, FS726Tv2, and FS728TLP Smart Switches
default
deny all traffic
rule that is the last rule of the MAC ACL table. (MAC ACL rules
have a lower priority than IP ACL rules.)
2.
Applying the ACL to an interface in the inbound direction.
The smart switch allows ACLs to be bound to physical ports and LAGs. The smart switch
supports MAC ACLs and IP ACLs. An example of each is provided in the following sections.
MAC ACL Sample Configuration
The following example shows how to create a MAC-based ACL that permits Ethernet traffic
from the sales department on specified ports and denies all other traffic on those interfaces.
To create such a MAC-based ACL:
1.
Select
Security > ACL > Basic > MAC ACL
.
The MAC ACL screen displays.
2.
Create an ACL with the name Sales_ACL for the sales department of your network.
By default, this ACL is bound on the inbound direction, which means the smart switch
examines traffic as it enters the port.
For more information about creating named MAC ACLs, see
Manage MAC ACL Names
on
page
197.
3.
Select
Security > ACL > Basic > MAC Rules
.
The MAC Rules screen displays.
4.
Create a rule for the Sales_ACL with the following settings:
Field or Menu
Configuration Setting
ID
1
Action
Permit
Assign Queue
0
Redirect Interface
Do not select
Match Every
False
CoS
0
Destination MAC
01:02:1A:BC:DE:EF
Destination MAC Mask
00:00:00:00:FF:FF
EtherType Key.
Do not enter
EtherType User Value
Do not enter
Source MAC
02:02:1A:BC:DE:EF